In May of this year, the Clop ransomware gang exploited a MOVEit file transfer software vulnerability that exposed data from large companies such as Boots, British Airways, the BBC and thousands of other organisations.
Now, as first reported by BleepingComputer, the ransomware gang has created publicly accessible websites to leak the data stolen through the MOVEit exploit.
According to security researcher Dominic Alvieri, Clop created its first clearweb (publicly accessible) site to leak data stolen from business consulting firm PWC, which has since been taken offline.
Ransomware leak sites are typically hosted on open-source privacy networks that enable anonymous web-browsing, and harder for law enforcement to seize the infrastructure. This type of website, on the other hand, is hosted on the public internet, leading to the sites being indexed by search engines and amplified this way.
“While the MOVEit campaign may end up impacting over 1000 companies directly, and an order of magnitude more indirectly, a very, very small percentage of victims bothered trying to negotiate, let alone contemplated paying,” read a report by Coveware.
Those that did pay, handed out significantly more than the global average ransomware amount, which is $740,144 (£577.4), up 126% from the first quarter of 2023, says the report.
Coveware pins the earnings in the ballpark of $75-100m (£58.5-78m), “from just a small handful of victims that succumbed to very high ransom payments.”
Recommended
- Cyber Attack Targets UK HR Provider — BBC, Boots, British Airways Impacted
- Global Ransomware Attacks in June up 221% Year-on-year
- Report: Email Attacks Surge 464% as Ransomware Reigns Supreme
This leaves many companies and government organisations who were affected in the MOVEit exploit left to pay the ransom to get their data offline.
In a time where traditional ransomware attacks are harder to monetize, Clop’s zero-day MOVEit exploit targeted the source of thousands of companies’ file transfers to steal data from countless users at once.
Security researchers say the cybercrime group dramatically increased its average ransom demand in this campaign, and far surpassed its recent GoAnywhere data attack in which only 130 victims were breached.





